Skip to main content

cra-vulnerability-obligations

Stars30,096
Forks3,346
UpdatedJuly 27, 2026 at 16:51

Use when a user asks what the EU Cyber Resilience Act (CRA) means for their product, whether and when they must report a vulnerability or incident, or what a specific CVE triggers legally. Maps a product with digital elements to CRA scope, product classification, Annex I vulnerability-handling duties, and Article 14 reporting obligations โ€” every legal claim cited from official regulation text fetched live through the Ansvar Gateway MCP connector, joined with live CVE / CISA-KEV / EPSS vulnerability intelligence from the same connector.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly